PT-2026-109012 · Azure Linux · Cloud Hypervisor

Published

2026-09-29

·

Updated

2026-09-29

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response.
Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application.
CWE: CWE-476: NULL-pointer dereference
Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr ' on the command line, or OSSL CMP exec RR ses() with the certificate supplied via OSSL CMP CTX set1 p10CSR() through the API.
A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash.
The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected.
FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-105438

Affected Products

Cloud Hypervisor